Legal

Privacy Policy

ComplyFlo Waste LLC  ·  Last updated: May 16, 2026  ·  Effective upon posting

This Privacy Policy explains how ComplyFlo Waste LLC collects, uses, discloses, stores, and otherwise processes information through the ComplyFlo website, software platform, applications, customer portals, integrations, reports, and related services (collectively, the "Services"). Please read it carefully before using our Services.

1. Overview

ComplyFlo provides workflow, recordkeeping, and reporting software for environmental and operational use cases, including but not limited to wastewater facilities, municipal solid waste sites, compost sites, haulers, used cooking oil operations, and related industries. This Privacy Policy is intended to cover current and future ComplyFlo offerings.

This Privacy Policy should be read together with the ComplyFlo Terms and Conditions.

2. Scope

This Privacy Policy applies to:

  • Visitors to the ComplyFlo website
  • Trial users, subscribers, customers, and authorized users of the Services
  • Individuals whose information is submitted to the Services by customers or users
  • Business contacts, support requestors, implementation contacts, and vendor contacts

This Privacy Policy does not apply to third-party websites, systems, applications, or services that may integrate with or link to the Services. Those third parties have their own privacy practices and policies.

3. Categories of Information Collected

ComplyFlo may collect the following categories of information, depending on how the Services are used:

A. Account and Contact Information

  • Name, business name, and job title
  • Email address and phone number
  • Mailing address
  • Username and authentication details

B. Customer Operational and Reporting Data

Depending on the customer use case, ComplyFlo may process operational, reporting, and recordkeeping data submitted by customers — including facility identifiers, permit numbers, transporter identifiers, manifests, waste stream records, environmental measurements, disposal records, route or pickup information, uploaded forms, logs, attachments, and related workflow records.

This category may include personal information to the extent customer records contain names, phone numbers, signatures, email addresses, driver information, operator information, contact records, or other information associated with identifiable individuals.

C. Billing and Transaction Information

  • Billing contact details and subscription details
  • Payment-related information and invoices
  • Transaction history
Payment card data
Where ComplyFlo uses a third-party payment processor (currently Stripe), payment card information is handled directly by that provider and is not stored by ComplyFlo. ComplyFlo stores only payment reference IDs.

D. Usage and Device Information

  • IP address, device type, browser type, and operating system
  • Referring URLs, pages viewed, and app activity
  • Date and time of access
  • Crash logs and diagnostic information
  • Cookies and similar technologies

E. Communications and Support Information

  • Messages sent through contact forms, emails, and support requests
  • Chat messages and meeting notes
  • Implementation and training communications

F. Integration and Third-Party Source Data

If a customer connects third-party tools, ComplyFlo may receive data from those systems — such as SCADA systems, spreadsheets, laboratories, accounting tools, GPS or route systems, cloud storage tools, or other customer-authorized data sources.

4. How Information Is Collected

ComplyFlo may collect information:

  • Directly from users, customers, and website visitors
  • From customer uploads, forms, imports, and manual entry
  • Through integrations and APIs authorized by the customer
  • Automatically through cookies, analytics tools, logs, and similar technologies
  • From service providers, implementation partners, payment providers, or other third parties acting on the customer's instructions or in connection with the Services

5. Purposes of Processing

ComplyFlo may use information for the following purposes:

  • To provide, maintain, host, secure, and improve the Services
  • To create and manage accounts and subscriptions
  • To authenticate users and manage access permissions
  • To process uploads, records, reports, exports, dashboards, and integrations
  • To provide customer support, onboarding, implementation, and training
  • To communicate about accounts, service updates, invoices, security matters, and support issues
  • To monitor usage, troubleshoot problems, analyze performance, and improve product functionality
  • To protect against fraud, abuse, unauthorized access, and security incidents
  • To comply with legal obligations, respond to lawful requests, and enforce agreements
  • To conduct limited marketing and business development activities, subject to applicable law and user choices

6. Legal Bases and Texas Privacy Considerations

For customers and users in Texas, ComplyFlo may be subject to the Texas Data Privacy and Security Act (TDPSA) depending on the company's size, activities, and the types of personal data processed. TDPSA generally requires a reasonably accessible privacy notice, data minimization, reasonable security measures, and processes for consumer rights requests, subject to the law's applicability thresholds and exemptions.

ComplyFlo may process personal data when reasonably necessary to provide requested services, operate the business, comply with law, protect security, fulfill contractual obligations, or pursue legitimate business purposes consistent with applicable law.

7. Cookies and Analytics

ComplyFlo may use cookies, pixels, SDKs, local device identifiers, and similar technologies to operate the website and Services, remember preferences, authenticate sessions, improve performance, understand engagement, and support analytics.

Cookie preferences
You can control cookie preferences through your browser settings. Disabling non-essential cookies on our marketing website will not affect your ability to use the ComplyFlo application. Session cookies required for authentication are strictly necessary and cannot be disabled without breaking core functionality.

8. How Information Is Shared

ComplyFlo does not sell personal information. We may share information in the following circumstances:

A. Service Providers and Vendors

With hosting providers, infrastructure providers, customer support vendors, analytics providers, payment processors, communications providers, consultants, and other vendors that process information on ComplyFlo's behalf. These include Supabase (Lovable Cloud) for database and hosting, Stripe for payment processing, and Google (Gemini) for AI-assisted data extraction.

B. Customer-Directed Sharing

With third-party systems, integrations, consultants, regulators, laboratories, contractors, or other recipients when directed or authorized by the customer or user.

C. Business Transactions

In connection with a merger, acquisition, financing, sale of assets, reorganization, bankruptcy, or similar corporate event. We will notify active subscribers before their information becomes subject to a different privacy policy.

D. Legal and Safety Reasons

To comply with law, subpoena, court order, government request, enforcement action, or audit, or to protect the rights, safety, property, users, the public, or the Services.

E. Affiliates and Advisors

With affiliated entities, insurers, auditors, lawyers, accountants, and professional advisors, as reasonably necessary for business operations and legal compliance.

9. Customer-Controlled Data and Controller / Processor Roles

In many cases, ComplyFlo acts as a service provider, processor, or contractor on behalf of business customers who control the data loaded into the Services. In those cases, the customer determines the purposes and means of processing certain customer-controlled information, and individuals may need to direct some privacy requests to the relevant customer.

ComplyFlo may also act as a controller for data relating to its own website visitors, business contacts, account administrators, billing contacts, and product usage analytics, depending on the context.

10. Data Retention

ComplyFlo may retain personal information and customer data for as long as reasonably necessary to provide the Services, maintain business records, support legitimate business operations, comply with contracts, resolve disputes, enforce agreements, protect security, satisfy legal obligations, and retain necessary audit trails.

Retention periods may vary depending on:

  • The type of information and customer subscription status
  • Applicable legal, tax, accounting, environmental, or contractual requirements
  • Backup, archival, and disaster recovery practices
  • Whether deletion would impair fraud prevention, security, dispute resolution, or audit integrity
Manifest and compliance record retention
Regulatory requirements mandate a minimum of 3 years for most manifest and compliance records. ComplyFlo stores these records permanently to support long-term audit readiness, unless a customer requests deletion and applicable law permits it.

When information is no longer needed, ComplyFlo may delete, aggregate, or de-identify it, subject to legal and operational requirements.

11. Data Security

ComplyFlo uses commercially reasonable administrative, technical, and organizational measures designed to protect information against unauthorized access, disclosure, alteration, and destruction. Such measures may include:

  • Access controls and role-based permissions
  • Encryption in transit (TLS) for all data transmitted between your browser and our servers
  • Database-level row-level security enforced through Supabase
  • Secure authentication and multi-factor authentication support
  • Audit logging of every edit, approval, and status change
  • Vendor management, monitoring, backups, and incident response processes
Security limitation
No method of transmission or storage is completely secure. ComplyFlo cannot guarantee absolute security. If you become aware of a security concern related to your account, please contact us immediately at info@complyflowaste.com.

12. International and Cross-Border Data Transfers

ComplyFlo may store or process information in the United States or other jurisdictions where ComplyFlo or its service providers operate. If ComplyFlo serves users outside the United States in the future, additional disclosures, safeguards, or transfer mechanisms may be required depending on where the data originates and where it is processed.

13. Privacy Rights and Choices

Depending on applicable law and your location, you may have rights to request access, correction, deletion, portability, or restrictions relating to your personal data, and may have the right to appeal certain privacy decisions.

To exercise applicable privacy rights, submit a request using the contact information in Section 18 below. ComplyFlo may need to verify your identity and authority before processing a request, and may deny or limit requests where permitted by law — including where the data is controlled by a business customer or must be retained for legal, security, or operational reasons.

14. Children's Privacy

The Services are intended for business and operational use and are not directed to children. ComplyFlo does not knowingly collect personal information directly from children in a manner requiring parental consent under applicable law. If ComplyFlo learns that it has collected personal information from a child in violation of applicable law, ComplyFlo may take steps to delete that information.

15. Public, Regulatory, and Customer Disclosures

ComplyFlo customers may use the Services in industries that involve public reporting, inspections, records requests, regulatory audits, or government submissions. Some information handled through the Services may therefore be disclosed by customers, regulators, or third parties under applicable law, permit rules, subpoenas, open records laws, or other legal processes.

No exemption guarantee
ComplyFlo does not guarantee that records or data stored in the Services will be exempt from public disclosure or entitled to confidential treatment under any law.

16. Third-Party Services and Links

The Services may contain links to third-party websites, portals, forms, maps, payment pages, or integration partners. ComplyFlo is not responsible for the privacy practices of those third parties. Users should review the privacy notices of third-party services before providing information to them.

17. Changes to This Privacy Policy

ComplyFlo may update this Privacy Policy from time to time. The revised version will become effective when posted or on the effective date stated in the updated policy.

When we make material changes, we will update the "Last updated" date at the top of this page and send an email notification to account administrators. Where required by law, we will provide additional notice or obtain consent for material changes.

18. Contact Information

Questions, privacy requests, and privacy complaints should be directed to:

Contact us
Questions about this Privacy Policy?

ComplyFlo Waste LLC
29607 Pewter Run Lane
Katy, TX 77494

Email: info@complyflowaste.com
Website: complyflowaste.com

We will respond to all privacy-related inquiries within 30 days.